Dettaglio notizia

Data 06/07/2026
Titolo Malicious npm Rollup Polyfills Linked to Lazarus Target Developer Environments
Contesto Researchers identified a malicious npm supply-chain campaign that impersonated Rollup polyfill tooling to compromise developer workstations and CI/build systems. The primary packages, rollup-packages-polyfill-core and rollup-runtime-polyfill-core, mimicked legitimate Rollup-related projects and used staged dependencies including swift-parse-stream, quirky-token, react-icon-svgs, and rollup-plugin-polyfill-connect to trigger a multi-stage infection chain. The malware fetched obfuscated code from JSONKeeper, decrypted additional payloads retrieved from 216.126.236.244, and executed them locally while using evasive checks to avoid some analysis and cloud development environments.

The final payloads gave attackers remote access and enabled theft of browser data, crypto-wallet information, files, clipboard contents, and other developer secrets such as source code, tokens, SSH keys, and cloud credentials. JFrog said the layered package structure, lookalike naming, and tradecraft resemble earlier Lazarus-linked npm operations, while additional reporting tied the activity to a broader North Korea-linked supply-chain effort referred to as PolinRider. Some malicious packages were replaced with security-holding versions, but others remained available at the time of reporting, prompting guidance to remove the packages, treat affected hosts as compromised, rotate credentials, and block related outbound traffic.
Fonte https://mallory.ai/stories/019f1b39-0a61-7fb2-bb3d-434f2cffeebf
Discussione? Parliamone sul Forum